Security Policy
How to report a vulnerability and what we promise in return, what protects the Service, and exactly what we will do if we are breached. It states what we actually have, and names what we do not.
- In force from
- Version
- 1.0
- Issued by
- OmniOS OÜ
1Reporting a vulnerability
Email [email protected]. Tell us what you found, where, and how to reproduce it. A proof of concept helps; a video is fine; a scanner report on its own usually is not.
- Acknowledgement
- Within 2 working days.
- First assessment
- Within 5 working days, with our view of severity and whether we are treating it as a vulnerability.
- Fix target
- Critical within 7 days, high within 30, medium within 90. If we will miss a target we tell you and say why.
- Disclosure
- Coordinated. We ask you to hold publication until a fix is deployed, and we will not stall — 90 days from your report is the outer limit, after which publish regardless.
- Credit
- We name you in the changelog if you want to be named, and stay quiet if you do not.
We do not run a paid bug bounty. We are a small company and would rather say that plainly than imply a reward we will not pay.
2Safe harbour for good-faith research
If you follow the rules below, we will not pursue legal action against you, and we will say so in writing to anyone who asks. We treat your research as authorised for the purposes of computer-misuse law and of our own Terms.
- Test only against your own account and your own data. Do not access, modify or retain anyone else's.
- Stop as soon as you have confirmed a vulnerability. Do not pivot deeper to see how far it goes.
- If you access personal data by accident, stop, tell us immediately, and delete it. Do not keep a copy as proof.
- No denial of service, no volumetric or stress testing, no spam, no social engineering of our people or our providers, and no physical attacks.
- Do not use a finding to extract data, place trades, or gain paid entitlements you have not bought.
- Give us reasonable time to fix it before you publish.
Break those and the safe harbour does not apply. In particular, an extortion demand attached to a report is not research, and we will treat it as what it is.
3How the Service is protected
| Area | What we do |
|---|---|
| Transport | TLS 1.2 or better everywhere, HSTS with a two-year max-age and preload, and a restrictive content security policy. |
| Authentication | Salted password hashing with a modern key-derivation function; signed HttpOnly, Secure, SameSite=Strict session cookies with a 24-hour lifetime; OAuth with PKCE and single-use state nonces. |
| Authorisation | Entitlements checked server-side on every request. A client that asks for data above its plan is refused by the API, not hidden by the interface. |
| Data location | Hosted in the European Union, in Frankfurt, Germany. See the sub-processors page for everything that sits outside it. |
| Backups | Encrypted, scheduled, and verified by restore drills rather than assumed to work. |
| Access control | Production access limited to those who need it, over authenticated channels, with an append-only audit log. |
| Abuse resistance | Per-plan rate limiting, anomaly detection on authentication, and a WAF in front of everything. |
| Dependencies | Automated vulnerability scanning, with security updates taking priority over feature work. |
| Payments | Card data goes to Stripe directly. We never receive or store a full card number. |
We hold no ISO 27001 or SOC 2 certification, and we do not imply one. If your procurement process needs a security questionnaire completed, write to [email protected] and we will answer it honestly.
4If we suffer a breach
We maintain a written incident response procedure. In an incident involving personal data:
- We contain it first, then investigate scope, then notify. In that order.
- Where the breach is likely to risk your rights and freedoms, we notify the Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate) within 72 hours of becoming aware of it, as Article 33 GDPR requires.
- Where the risk to you is high, we tell you directly and without undue delay, in plain language: what happened, what data was involved, what we have done, and what you should do — Article 34 GDPR.
- Business customers with a data processing agreement are notified without undue delay so they can meet their own obligations.
- We publish a post-incident summary once the incident is closed. We would rather write that than have someone else write it for us.
We will not describe a breach as a "security incident affecting a limited number of accounts" when it is not, and we will not delay telling you in order to finish the investigation first.
5Your part
- Use a unique password, or sign in with Google.
- Treat API keys like passwords. Rotate one you have pasted anywhere public, immediately.
- Tell us at [email protected] the moment you suspect your account is compromised.
- Remember that we will never ask you for your password, and never ask you to move funds anywhere. Anyone who does is not us.
OmniOS OÜ never takes custody of crypto-assets and never asks for a private key or seed phrase, for any reason, ever.